UT Physicians
ent_bafe01430b2a14d4b965a200
Disclosures
4
HHS OCR · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
18,500
nationwide · HHS OCR TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UT Physicians
- Normalized
- ut physicians— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- TEXASHHS OCRas victim2019-05-10
University Medical Center Physicians reported to HHS on 2019-05-10 a Unauthorized Access/Disclosure affecting 3300 individuals. Breached information located on Network Server, Other. Two employees shared PHI via a shared drive and one sent PHI to a personal email account. Names, addresses, DOB, and treatment info were exposed. Employees were sanctioned and workforce retrained.
- TEXASHHS OCRas victim2018-08-16
University Medical Center Physicians reported to HHS on 2018-08-16 a Hacking/IT Incident affecting 18500 individuals. Breached information located on Email. An unauthorized user compromised a workforce member's email account through a phishing campaign, exposing PHI including names, DOB, SSN, addresses, and treatment info. The CE improved safeguards, updated policies, trained staff, and notified HHS, individuals, and media.
- TEXASHHS OCRas victim2018-05-18
UT Physicians (University of Texas Physicians), a Healthcare Provider in TX, reported to HHS OCR on 2018-05-18 an Unauthorized Access/Disclosure affecting 2,793 individuals. On May 7, 2018, a workforce member inadvertently inserted multiple patient email addresses into the 'To' field instead of 'BCC', exposing patient email addresses to other patients. Breached information was located in Email. The CE implemented technical safeguards, retrained staff, and notified affected individuals and the media. OCR obtained corrective action assurances.
- TEXASHHS OCRas victim2013-08-28
UT Physicians (TX) reported to HHS on 2013-08-28 a Theft affecting 596 individuals. An unencrypted laptop attached to an EMG nerve device and stored in a locked, key-card-secured closet was stolen from the facility. The ePHI included patients' names, dates of birth, medical record numbers, and EMG values. Following the breach, UT Physicians replaced the device with an encrypted laptop, improved physical safeguards, inventoried all ePHI-containing devices, and provided breach notification to HHS, affected individuals, and media. OCR reviewed the CE's risk analysis and risk management plan.